PT-2024-22463 · Unknown · Niushop B2B2C

Trung

·

Published

2024-03-22

·

Updated

2024-08-23

·

CVE-2024-28560

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Niushop B2B2C versions 5.3.3 and earlier
Description The issue allows an attacker to escalate privileges via the deleteArea() function of the Address.php component or the setPrice() function of the Goodsbatchset.php component. This is a SQL injection vulnerability.
Recommendations For versions 5.3.3 and earlier, as a temporary workaround, consider disabling the deleteArea() function and the setPrice() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-28560

Affected Products

Niushop B2B2C